Account

Security

Security controls are enforced server-side. Each control below activates only after authentication is connected.

Protection incomplete
Not enabled

Two-factor authentication

Time-based one-time codes required for login, withdrawal and API key creation.

Not configured

Withdrawal allowlist

Restrict withdrawals to pre-approved addresses with a mandatory cooling period.

Not set

Anti-phishing code

A personal code included in every platform email so spoofed mail is obvious.

Not enabled

Login approvals

Require confirmation from a trusted device when signing in from a new location.

Active sessions

No session data

Device, IP, location and last-seen time are listed per session with remote sign-out.

Security activity

No events

Password changes, 2FA updates and withdrawal approvals are logged immutably.